Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Wordpress von Automattic
WordPress 7.1.3 – Wartungs- und Sicherheitsupdate
WordPress 7.1.3 enthält 7 Sicherheitskorrekturen und 4 Fehlerbehebungen, darunter Korrekturen für Stored XSS auf der Kommentarseite, SQL-Injection im WXR-Export und die Offenlegung von Kommentaren privater Beiträge, und sollte sofort installiert werden.
This security and maintenance release features 7 security fixes and 4 bug fixes.
Because this is a security release, it is recommended that you update your sites immediately.
You can download WordPress 7.1.3 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.
Security updates included in this release
The security team would like to thank the following people and organizations for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:
- A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
- A DoS issue in the
WP_Http::make_absolute_url()method, reported by Anthropic - A second-Order SQL injection in WordPress WXR export, reported by Anthropic
- A weakness allowing Author role users to sticky posts, reported by Anthropic
- Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack …